Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the kernel handles specific types of network traffic processed by BPF (Berkeley Packet Filter) programs. An exploit results in a complete system denial of service (kernel panic), impacting availability and ongoing operations.
Technical details
A vulnerability exists in net/ipv4/tcp_bpf.c within the Linux kernel due to improper handling of the 'copied' return value in tcp_bpf_sendmsg(). When messages are corked in psock->cork, flushing the last message can result in a sk_msg larger than the current message size. In tcp_bpf_send_verdict(), the 'copied' variable can become negative during error handling (e.g., __SK_DROP). This negative value is subsequently returned to sock_sendmsg_nosec, triggering a BUG_ON in net/socket.c. A local attacker can exploit this to cause a kernel panic (Denial of Service). The fix ensures that the function returns an error code instead of a negative byte count.
Affected products
- Linux Linux Kernel 4.17 to 5.4.284, 5.5 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.110, 6.2 to 6.6.51, 6.7 to 6.10.10, 6.11-rc1 to 6.11-rc6
Timeline
- 2024-08-20: other: Patch authored
- 2024-09-18: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/126d72b726c4cf1119f3a7fe413a78d341c3fea9
- https://git.kernel.org/stable/c/3efe53eb221a38e207c1e3f81c51e4ca057d50c2
- https://git.kernel.org/stable/c/6f9fdf5806cced888c43512bccbdf7fefd50f510
- https://git.kernel.org/stable/c/78bb38d9c5a311c5f8bdef7c9557d7d81ca30e4a
- https://git.kernel.org/stable/c/810a4e7d92dea4074cb04c25758320909d752193
- https://git.kernel.org/stable/c/c8219a27fa43a2cbf99f5176f6dddfe73e7a24ae
- https://git.kernel.org/stable/c/fe1910f9337bd46a9343967b547ccab26b4b2c6e